GHSA-hxxf-q3w9-4xgw

    Dashboard / Vulnerabilities / GHSA-hxxf-q3w9-4xgw

    GHSA-hxxf-q3w9-4xgw

    Published: 12 Jul 2018Last Modified: 14 Sept 2021

    Summary: Malicious Package in eslint-scope

    Details: Version 3.7.2 of `eslint-scope` was published without authorization and was found to contain malicious code. This code would read the users `.npmrc` file and send any found authentication tokens to 2 remote servers. ## Recommendation The best course of action if you found this package installed in your environment is to revoke all your npm tokens. You can find instructions on how to do that here. https://docs.npmjs.com/getting-started/working_with_tokens#how-to-revoke-tokens

    Affected packages

    Package

    Name: eslint-scope

    Purl: pkg:npm/eslint-scope

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 3.7.2
    Fixed -3.7.3

    Affected versions

    3.7.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High